IOC Report
mipsel.elf

loading gif

Files

File Path
Type
Category
Malicious
mipsel.elf
ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, no section header
initial sample
malicious
/tmp/Infected.log
ASCII text, with CRLF line terminators
dropped

Processes

Path
Cmdline
Malicious
/tmp/mipsel.elf
/tmp/mipsel.elf
/tmp/mipsel.elf
-
/tmp/mipsel.elf
-

URLs

Name
IP
Malicious
https://developers.google.com/search/docs/advanced/crawling/overview-google-crawlers)
unknown
http://upx.sf.net
unknown
http://www.spidersoft.com)
unknown
http://help.yahoo.com/help/us/ysearch/slurp)
unknown
http://www.google.com/bot.html)
unknown
http://www.google.com/mobile/adsbot.html)
unknown

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.24

IPs

IP
Domain
Country
Malicious
181.214.231.152
unknown
Chile

Memdumps

Base Address
Regiontype
Protect
Malicious
7f51f8459000
page execute read
malicious
7f51f8459000
page execute read
malicious
7f51f84a3000
page read and write
558845bc2000
page read and write
7f527f7c5000
page read and write
7f528049f000
page read and write
7f527fe47000
page read and write
7f528049f000
page read and write
7f5278000000
page read and write
7f5280195000
page read and write
55884391b000
page execute read
7f5280376000
page read and write
558843ba3000
page read and write
7f51f8180000
page execute and read and write
7f51f84a3000
page read and write
7f51f8180000
page execute and read and write
55884391b000
page execute read
7f52804a7000
page read and write
7f5278021000
page read and write
558845bc2000
page read and write
7f527efbd000
page read and write
7f527fa83000
page read and write
7f5280376000
page read and write
558845bab000
page execute and read and write
7f527efbd000
page read and write
7f527fe64000
page read and write
558846784000
page read and write
558846784000
page read and write
7f5278021000
page read and write
7f527f7c5000
page read and write
558843bad000
page read and write
7f5278000000
page read and write
7ffca187e000
page read and write
558843ba3000
page read and write
7ffca187e000
page read and write
7f527fa83000
page read and write
7f527fe47000
page read and write
7f527fe24000
page read and write
7ffca19f5000
page execute read
7f52804ec000
page read and write
7f527fe64000
page read and write
7ffca19f5000
page execute read
7f527f7d3000
page read and write
558845bab000
page execute and read and write
7f527fe24000
page read and write
7f527f7d3000
page read and write
7f52804ec000
page read and write
558843bad000
page read and write
7f5280195000
page read and write
7f52804a7000
page read and write
There are 40 hidden memdumps, click here to show them.